CVE-2019-9649: Coreftp Core FTP
Medium severity, CVSS 5.3. EPSS: 14.5% chance of exploitation in the next 30 days.
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.
Affected products
- Coreftp Core FTP: version 2.0 only
Published 2019-03-22. Last modified 2026-06-17.